The package has 15 runtime dependencies and no repository security policy, increasing upkeep and response risk. Its documentation, license, stable versioning, and matching source repository provide useful transparency, but maintenance evidence is limited.
52%
Total Score
50
50
92
75
The package declares 15 runtime dependencies, including framework, database, logging, translation, and extension requirements. This creates a relatively broad maintenance and compatibility surface for an inactive package.
The latest release was about 6 years ago, with no releases in the last 12 months. Earlier releases arrived roughly every 42 days, but the long current gap is a maintenance concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with an inactive project. The repository is not archived, but that does not show ongoing maintenance.
The linked repository has no security policy. That reduces transparency about vulnerability reporting and response, especially given the package's broad runtime dependency set.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version * | — | — |
psr/cache Version * | — | — |
cache/cache Version * | — | — |
doctrine/dbal Version * | — | — |
monolog/monolog Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.